← All topics

CIPP — manage M365 tenants easily

approved

Using CyberDrain CIPP to run multi-tenant Microsoft 365 operations: standards, GDAP, bulk actions, and consistent day-to-day administration.

Audiences: ae, tech · Tags: m365, multi-tenant, cipp, cyberdrain · Last verified: 2026-07-16

Teach module

# Teach — CIPP for multi-tenant M365 operations

## Core truths

- CIPP (CyberDrain Improved Partner Portal) is an open-source, MSP-focused portal for administering many Microsoft 365 tenants from a single interface.
- It uses GDAP (granular delegated admin privileges) relationships, aligning with Microsoft's model for least-privilege partner access.
- Standards let you define desired tenant settings (for example, disabling shared mailbox sign-in, enabling unified audit log) and apply or enforce them across tenants.
- Common day-to-day jobs — user offboarding, mailbox permissions, MFA state review, license reporting — can be done per tenant or in bulk without portal-hopping.
- Because CIPP wraps Microsoft Graph, actions are consistent and scriptable rather than dependent on which admin portal a setting lives in this month.

## Common myths to correct

- "Open source means unsupported" — CIPP has an active community, and a hosted/sponsored option exists for teams that do not want to self-host; either way, you own your operational process.
- "It replaces our RMM/PSA" — CIPP is tenant administration, not device management or ticketing; it complements those tools.
- "GDAP is just DAP with extra steps" — GDAP scopes roles per tenant and is what Microsoft requires; CIPP makes managing those relationships practical.

## Pitfalls

- Deploying CIPP without agreeing internally which standards are enforced versus merely reported — silent enforcement surprises engineers.
- Giving every technician full CIPP access instead of using role-based permissions within the tool.
- Treating offboarding as done because the account is disabled: the full offboarding flow (sessions revoked, mailbox converted, licences reclaimed) is the value, use all of it.
- Forgetting that standards run on a schedule: a manual portal change may be reverted by an enforced standard, which looks like a bug to the unaware.

Apply module

# Apply — discovery, objections, and talk tracks

## Discovery questions

- How many different admin portals does a technician touch to fully offboard one user today?
- How do you check MFA coverage across every tenant you manage — and how current is that answer?
- When Microsoft changes a portal layout, how much time does your team lose relearning where settings live?
- How do you evidence to a client that their tenant matches your security standard?
- What is your current process for reclaiming unused licences across tenants?

## Objections and responses

- "We manage fine in the portals." — Fine at what cost? Count minutes per task per tenant; multi-tenant portals turn a 20-minute job into a 2-minute one.
- "Self-hosting is a burden." — The hosted option removes that; if self-hosting, the deployment is well documented and the operational win outweighs upkeep for most teams.
- "Another tool for the team to learn." — CIPP consolidates several portals into one; the learning curve replaces portal-hopping rather than adding to it.

## Talk tracks

- "One portal, every tenant, least-privilege by design" — leads with both efficiency and security posture.
- Frame standards as the multi-tenant guarantee: what you promise every client is true, provably, all the time.
- For AEs: the sale is the outcome (consistent, evidenced tenant management), not the tool name — CIPP is how delivery keeps that promise.

Convert module

# Convert — CTAs and next steps

## Approved CTAs

- Internal enablement: each engineer completes one full user offboarding through CIPP this week and notes the time taken versus the portal method.
- Offer clients a tenant health check: a standards report showing where their tenant deviates from our baseline.
- Propose bringing unmanaged or ad-hoc tenants under managed standards as a defined onboarding package.

## Next-step framing

- Tech sessions: next step is agreeing which standards are report-only versus enforced, then piloting on the MSP's own tenant.
- AE sessions: next step is booking tenant health check conversations with the three clients most likely to fail an audit.
- Never position CIPP output as a compliance certificate; it is evidence that supports compliance work.

Demo steps

# Demo — everyday multi-tenant jobs in CIPP

1. Show the tenant switcher and the all-tenants dashboard to establish the single-pane starting point.
2. Run a user offboarding on a test account: disable sign-in, revoke sessions, convert mailbox to shared, remove licences — one wizard, one screen.
3. Open the MFA report across all tenants and highlight how coverage gaps surface instantly.
4. Show standards: pick one standard (for example, enable unified audit log), show which tenants comply, and apply it to a pilot tenant.
5. Show the licence report across tenants and identify unassigned paid licences.
6. Open the GDAP relationship view to show scoped, per-tenant role assignments.

## Pre-demo checklist

- Test user account created in the pilot tenant and safe to offboard.
- Standards selected for the demo are report-only in advance, so nothing enforces mid-session.
- Client-identifiable tenant names hidden for external audiences.

Claims policy

# Claims — CIPP

## Allowed claims

- CIPP provides a single portal for administering multiple Microsoft 365 tenants.
- CIPP uses GDAP relationships in line with Microsoft's partner access model.
- Standards can report on or enforce defined tenant settings across tenants.
- Common admin tasks (offboarding, MFA reporting, licence reporting, mailbox management) can be performed per tenant or in bulk.
- CIPP is open source, with a hosted option available for teams that prefer not to self-host.

## Forbidden / needs-human-review claims

- Specific sponsorship/hosting pricing — verify current figures before quoting.
- Any guaranteed time savings percentage; use illustrative comparisons only.
- Claims that a specific standard exists for a specific setting — verify against the current CIPP release before stating.
- Claims about compliance certification outcomes.
- Statements about CIPP's roadmap or unreleased features.